CISA Turns to Cyber Decoys to Catch Attackers Inside Critical Infrastructure Networks
An attacker who has stolen legitimate credentials and learned to use the tools already sitting inside a network can be remarkably difficult to spot. There may be no conspicuous malware announcing the intrusion, no obviously malicious account and, for a time, little to distinguish the attacker from someone who belongs there. CISA wants critical infrastructure operators to give such intruders something they cannot safely touch.
